Mattermost notified all users in the channel when using WebSockets to respond individually
Moderate severity
GitHub Reviewed
Published
Jan 2, 2024
to the GitHub Advisory Database
•
Updated Aug 7, 2024
Description
Published by the National Vulnerability Database
Jan 2, 2024
Published to the GitHub Advisory Database
Jan 2, 2024
Reviewed
Jan 3, 2024
Last updated
Aug 7, 2024
Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.
References